Composer package intelligence

drupal/core Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Composer package drupal/core, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
5
Known exploited vulnerabilities affecting drupal/core
In CISA KEV
5
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
1
drupal/core KEV with sensor-observed exploitation activity

Review drupal/core exploitation against the versions you run

All five exploited drupal/core vulnerabilities tracked here are also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested drupal/core vulnerabilities

5 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2026-9082

Drupal core - Highly critical - SQL injection - SA-CORE-2026-004

In CISA 01 Jun 2026
CVE-2018-7600

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an...

In CISA 03 Nov 2021
CVE-2020-13671

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension...

In CISA 18 Jan 2022
CVE-2019-6340

Drupal core - Highly critical - Remote Code Execution

In CISA 25 Mar 2022
CVE-2018-7602

Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004

In CISA 13 Apr 2022

Recurring weakness patterns

Improper Input Validation, Unrestricted Upload of File with Dangerous Type, and Deserialization of Untrusted Data account for mapped occurrences across this drupal/core KEV portfolio.

Browse all KEVs →